<?xml version="1.0" encoding="ISO-8859-1"?>

<!DOCTYPE rss PUBLIC "-//Netscape Communications//DTD RSS 0.91//EN"
 "http://my.netscape.com/publish/formats/rss-0.91.dtd">

<rss version="0.91">

<channel>
<title>abnormalpenguin.com</title>
<link>http://www.abnormalpenguin.com/</link>
<description>PHP-Nuke Powered Site</description>
<language>en-us</language>

<item>
<title>Offical Mirrors</title>
<link>http://www.abnormalpenguin.com//modules.php?name=News&amp;file=article&amp;sid=335</link>
<description>&lt;i&gt;Message-ID:&lt;/i&gt; &lt;a href=&quot;news:ct199g$1j4$1@news.ngi.it&quot;&gt;&amp;lt;ct199g$1j4$1@news.ngi.it&amp;gt;&lt;/a&gt;&lt;br&gt;
&lt;i&gt;From:&lt;/i&gt; Andreas Liebschner &amp;lt;fizban@slackware.com&amp;gt;&lt;br&gt;
&lt;i&gt;Newsgroups:&lt;/i&gt; alt.os.linux.slackware&lt;br&gt;
&lt;i&gt;Subject: Re:&lt;/i&gt; ftp.scarlet.be no longer mirroring?&lt;br&gt;
&lt;i&gt;Date:&lt;/i&gt; Sun, 23 Jan 2005 23:46:20 +0100&lt;br&gt;
&lt;i&gt;References:&lt;/i&gt; &lt;a href=&quot;news:csunid$bki$1@skeeter.ucdavis.edu&quot;&gt;&amp;lt;csunid$bki$1@skeeter.ucdavis.edu&amp;gt;&lt;/a&gt; &lt;a href=&quot;news:b0p5v01ubb783d04m0kmk4cjl7ph51scmo@4ax.com&quot;&gt;&amp;lt;b0p5v01ubb783d04m0kmk4cjl7ph51scmo@4ax.com&amp;gt;&lt;/a&gt;&lt;br&gt;
&lt;i&gt;Lines:&lt;/i&gt; 37&lt;br&gt;
&lt;i&gt;Organization:&lt;/i&gt; NGI SpA - www.ngi.it&lt;br&gt;
&lt;i&gt;NNTP-Posting-Host:&lt;/i&gt; 81-174-11-144.f5.ngi.it&lt;br&gt;
&lt;i&gt;Mime-Version:&lt;/i&gt; 1.0&lt;br&gt;
&lt;i&gt;Content-Type:&lt;/i&gt; text/plain; charset=ISO-8859-1; format=flowed&lt;br&gt;
&lt;i&gt;Content-Transfer-Encoding:&lt;/i&gt; 7bit&lt;br&gt;
&lt;i&gt;X-Trace:&lt;/i&gt; news.ngi.it 1106520176 1636 81.174.11.144 (23 Jan 2005 22:42:56 GMT)&lt;br&gt;
&lt;i&gt;X-Complaints-To:&lt;/i&gt; abuse@ngi.it&lt;br&gt;
&lt;i&gt;NNTP-Posting-Date:&lt;/i&gt; Sun, 23 Jan 2005 22:42:56 +0000 (UTC)&lt;br&gt;
&lt;i&gt;User-Agent:&lt;/i&gt; Mozilla Thunderbird 0.9 (X11/20041103)&lt;br&gt;
&lt;i&gt;X-Accept-Language:&lt;/i&gt; en-us, en&lt;br&gt;
&lt;i&gt;In-Reply-To:&lt;/i&gt; &lt;a href=&quot;news:b0p5v01ubb783d04m0kmk4cjl7ph51scmo@4ax.com&quot;&gt;&amp;lt;b0p5v01ubb783d04m0kmk4cjl7ph51scmo@4ax.com&amp;gt;&lt;/a&gt;&lt;br&gt;
&lt;i&gt;X-Enigmail-Version:&lt;/i&gt; 0.89.0.0&lt;br&gt;
&lt;i&gt;X-Enigmail-Supports:&lt;/i&gt; pgp-inline, pgp-mime&lt;br&gt;
&lt;br&gt;
Mark Post wrote:&lt;br&gt;
&lt;br&gt;
&gt; It's probably due to the same problem that I've been seeing with always&lt;br&gt;
&gt; getting:&lt;br&gt;
&gt; opening tcp connection to ftp.slackware.com port 873&lt;br&gt;
&gt; @ERROR: max connections (25) reached - try again later&lt;br&gt;
&gt; rsync: connection unexpectedly closed (0 bytes received so far) [receiver]&lt;br&gt;
&gt; rsync error: error in rsync protocol data stream (code 12) at io.c(359)&lt;br&gt;
&gt; &lt;br&gt;
&gt; &lt;br&gt;
&gt; That's been going on for some time now.  It's almost like someone is running&lt;br&gt;
&gt; a DOS attack against the server.  With a max of 25 connections, that&lt;br&gt;
&gt; wouldn't be too hard.&lt;br&gt;
&lt;br&gt;
Hi Mark, :-)&lt;br&gt;
&lt;br&gt;
We will be pointing ftp.slackware.com to some other place (we meant to &lt;br&gt;
do it some time ago, but with Pat's personal issues it just went low on &lt;br&gt;
priority) as soon as possible, and in the mean time we already have &lt;br&gt;
another place where Pat pushes updates to&lt;br&gt;
&lt;br&gt;
I'm not going to write it on this newsgroup because then everyone would &lt;br&gt;
start using it, and we'd be forced to login/pass restrict it for mirrors &lt;br&gt;
only.&lt;br&gt;
&lt;br&gt;
Anyway, if you or any mirror admin (just those listed on /getslack) is &lt;br&gt;
having problems rsyncing from ftp.slackware.com, drop me an email at &lt;br&gt;
mirrors@ or fizban@ and I'll point you out to the right direction - as &lt;br&gt;
far as I know, ftp.scarlet.be should be aware of that server already, &lt;br&gt;
but I might be wrong.&lt;br&gt;
&lt;br&gt;
Also, to the users: if you notice a server &quot;not so up to date&quot;, please &lt;br&gt;
drop the server admin an email, and tell him/her to get in touch with &lt;br&gt;
me. For me it's impossible to go mirror by mirror and check.. so your &lt;br&gt;
help would be appreciated :-)&lt;br&gt;
&lt;br&gt;
Andreas</description>
</item>

<item>
<title>October 11th 2004 Updates</title>
<link>http://www.abnormalpenguin.com//modules.php?name=News&amp;file=article&amp;sid=334</link>
<description>&lt;b&gt;patches/packages/rsync-2.6.3-i486-1.tgz:&lt;/b&gt;&lt;br&gt;Upgraded to rsync-2.6.3. From the rsync NEWS file:&lt;br&gt;&lt;br&gt;A bug in the sanitize_path routine (which affects a non-chrooted rsync daemon) could allow a user to craft a pathname that would get transformed into an absolute path for certain options (but not for file-transfer names). If you're running an rsync daemon with chroot disabled, *please upgrade*, ESPECIALLY if the user privs you run rsync under is anything above &quot;nobody&quot;.&lt;br&gt;&lt;br&gt;Note that rsync, in daemon mode, sets the &quot;use chroot&quot; to true by default, and (in this default mode) is not vulnerable to this issue. I would strongly recommend against setting &quot;use chroot&quot; to false even if you've upgraded to this new package.&lt;br&gt;(* Security fix *)</description>
</item>

<item>
<title>October 4th 2004 Updates</title>
<link>http://www.abnormalpenguin.com//modules.php?name=News&amp;file=article&amp;sid=333</link>
<description>&lt;b&gt;patches/packages/getmail-4.2.0-noarch-1.tgz:&lt;/b&gt;&lt;br&gt;Upgraded to getmail-4.2.0. Earlier versions contained a local security flaw when used in an insecure fashion (surprise, running something as root that writes to user-controlled files or directories could allow the old symlink attack to clobber system files! :-)&lt;br&gt;From the getmail CHANGELOG:&lt;br&gt;&lt;br&gt;This vulnerability is not exploitable if the administrator does not deliver mail to the maildirs/mbox files of untrusted local users, or if getmail is configured to use an external unprivileged MDA. This vulnerability is not remotely exploitable.&lt;br&gt;&lt;br&gt;Most users would not use getmail in such as way as to be vulnerable to this flaw, but if your site does this package closes the hole. I'd also recommend not using getmail like this. Either run it as the user that owns the target mailbox, or deliver through an external MDA.&lt;br&gt;(* Security fix *)&lt;br&gt;&lt;br&gt;
&lt;b&gt;patches/packages/zlib-1.2.2-i486-1.tgz:&lt;/b&gt;&lt;br&gt;Upgraded to zlib-1.2.2. This fixes a possible DoS in earlier versions of zlib-1.2.x.&lt;br&gt;(* Security fix *)</description>
</item>

<item>
<title>September 19th 2004 Updates</title>
<link>http://www.abnormalpenguin.com//modules.php?name=News&amp;file=article&amp;sid=332</link>
<description>&lt;b&gt;patches/packages/cups-1.1.21-i486-1.tgz:&lt;/b&gt;&lt;br&gt;Upgraded to cups-1.1.21. This fixes a flaw where a remote attacker can crash the CUPS server causing a denial of service. For more details, see:&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0558&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0558&lt;/a&gt;&lt;br&gt;(* Security fix *)&lt;br&gt;&lt;br&gt;
&lt;b&gt;patches/packages/gtk+2-2.4.10-i486-1.tgz:&lt;/b&gt;&lt;br&gt;Upgraded to gtk+-2.4.10. This fixes security issues in the image loader routines that can crash applications.&lt;br&gt;(* Security fix *)&lt;br&gt;&lt;br&gt;
&lt;b&gt;patches/packages/mozilla-1.7.3-i486-1.tgz:&lt;/b&gt;&lt;br&gt;Upgraded to mozilla-1.7.3. The Mozilla page says this fixes some &quot;minor security holes&quot;. It also breaks Galeon and Epiphany, and new versions of these have still not appeared. In light of this, I think it's time to remove these Gecko-based browsers. The future is going to be Firefox and Thunderbird anyway, and I don't believe Galeon and Epiphany can be compiled against Firefox's libraries.&lt;br&gt;(* Security fix *)&lt;br&gt;&lt;br&gt;
&lt;b&gt;patches/packages/mozilla-plugins-1.7.3-noarch-1.tgz:&lt;/b&gt;&lt;br&gt;Changed plugin symlinks for Mozilla 1.7.3.&lt;br&gt;&lt;br&gt;
&lt;b&gt;patches/packages/xine-lib-1rc6a-i686-1.tgz:&lt;/b&gt;&lt;br&gt;Upgraded to xine-lib-1-rc6a. This release fixes a few overflows that could have security implications.&lt;br&gt;(* Security fix *)</description>
</item>

<item>
<title>September 13th 2004 Updates</title>
<link>http://www.abnormalpenguin.com//modules.php?name=News&amp;file=article&amp;sid=331</link>
<description>&lt;b&gt;patches/packages/samba-3.0.5-i486-3.tgz:&lt;/b&gt;&lt;br&gt;Patched two Denial of Service vulnerabilities in samba-3.0.5. For more details, see:&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0807&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0807&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0808&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0808&lt;/a&gt;&lt;br&gt;(* Security fix *)</description>
</item>

<item>
<title>September 10th 2004 Updates</title>
<link>http://www.abnormalpenguin.com//modules.php?name=News&amp;file=article&amp;sid=330</link>
<description>&lt;b&gt;patches/packages/proftpd-1.2.10-i486-1.tgz:&lt;/b&gt;&lt;br&gt;Upgraded to proftpd-1.2.10.</description>
</item>

<item>
<title>September 3rd 2004 Updates</title>
<link>http://www.abnormalpenguin.com//modules.php?name=News&amp;file=article&amp;sid=329</link>
<description>&lt;b&gt;patches/packages/glibc-2.3.2-i486-7.tgz:&lt;/b&gt;&lt;br&gt;Recompiled using 'strip -g' rather than 'strip --strip-unneeded' to avoid stripping symbols that are needed for debugging threads.  Thanks to those who reported this bug, especially Ricardo Nabinger Sanchez who sent in a sample thread program that made it easy to test for the problem (and confirm the fix worked).&lt;br&gt;&lt;br&gt;
&lt;b&gt;patches/packages/glibc-solibs-2.3.2-i486-7.tgz:&lt;/b&gt;&lt;br&gt;Recompiled using 'strip -g'.&lt;br&gt;&lt;br&gt;
&lt;b&gt;patches/packages/kdebase-3.2.3-i486-2.tgz:&lt;/b&gt;&lt;br&gt;Patched frame injection vulnerability in Konqueror. For more details, see:&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0721&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0721&lt;/a&gt;&lt;br&gt;(* Security fix *)&lt;br&gt;&lt;br&gt;
&lt;b&gt;patches/packages/kdelibs-3.2.3-i486-2.tgz:&lt;/b&gt;&lt;br&gt;Patched unsafe temporary directory usage, cross-domain cookie injection vulnerability for certain country specific domains, and frame injection vulnerability in Konqueror. For more details, see:&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0689&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0689&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0690&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0690&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0721&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0721&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0746&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0746&lt;/a&gt;&lt;br&gt;(* Security fix *)</description>
</item>

<item>
<title>October 11th 2004 Updates</title>
<link>http://www.abnormalpenguin.com//modules.php?name=News&amp;file=article&amp;sid=328</link>
<description>&lt;b&gt;patches/packages/rsync-2.6.3-i386-1.tgz:&lt;/b&gt;&lt;br&gt;Upgraded to rsync-2.6.3. From the rsync NEWS file:&lt;br&gt;&lt;br&gt;A bug in the sanitize_path routine (which affects a non-chrooted rsync daemon) could allow a user to craft a pathname that would get transformed into an absolute path for certain options (but not for file-transfer names). If you're running an rsync daemon with chroot disabled, *please upgrade*, ESPECIALLY if the user privs you run rsync under is anything above &quot;nobody&quot;.&lt;br&gt;&lt;br&gt;Note that rsync, in daemon mode, sets the &quot;use chroot&quot; to true by default, and (in this default mode) is not vulnerable to this issue. I would strongly recommend against setting &quot;use chroot&quot; to false even if you've upgraded to this new package.&lt;br&gt;(* Security fix *)</description>
</item>

<item>
<title>August 7th 2004 Updates</title>
<link>http://www.abnormalpenguin.com//modules.php?name=News&amp;file=article&amp;sid=327</link>
<description>&lt;b&gt;patches/packages/libpng-1.2.5-i486-1.tgz:&lt;/b&gt;&lt;br&gt;Upgraded to libpng-1.2.5 and patched possible security issues including buffer and integer overflows and null pointer references. These issues could cause program crashes, or possibly allow arbitrary code embedded in a malicious PNG image to execute. The PNG library is widely used within the system, so all sites should upgrade to the new libpng package.&lt;br&gt;For more details, see:&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0597&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0597&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0598&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0598&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0599&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0599&lt;/a&gt;&lt;br&gt;(* Security fix *)&lt;br&gt;&lt;br&gt;
&lt;b&gt;patches/packages/sox-12.17.4-i386-3.tgz:&lt;/b&gt;&lt;br&gt;Patched buffer overflows that could allow a malicious WAV file to execute arbitrary code.&lt;br&gt;(* Security fix *)</description>
</item>

<item>
<title>July 25th 2004 Updates</title>
<link>http://www.abnormalpenguin.com//modules.php?name=News&amp;file=article&amp;sid=326</link>
<description>&lt;b&gt;patches/packages/mod_ssl-2.8.19_1.3.31-i386-1.tgz:&lt;/b&gt;&lt;br&gt;Upgraded to mod_ssl-2.8.19-1.3.31. This fixes a security hole (ssl_log() related format string vulnerability in mod_proxy hook functions), so sites using mod_ssl should upgrade to the new version. Be sure to back up your existing key files first.&lt;br&gt;(* Security fix *)&lt;br&gt;&lt;br&gt;
&lt;b&gt;patches/packages/samba-2.2.10-i386-1.tgz:&lt;/b&gt;&lt;br&gt;Upgraded to samba-2.2.10. A buffer overrun has been located in the code used to support the 'mangling method = hash' smb.conf option. Affected Samba 2.2 installations can avoid this possible security bug by using the hash2 mangling method. Server installations requiring the hash mangling method are encouraged to upgrade to Samba v2.2.10 or v3.0.5.&lt;br&gt;For more details, see:&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0686&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0686&lt;/a&gt;&lt;br&gt;(* Security fix *)</description>
</item>

</channel>
</rss>